US9843598B2

Capture triggers for capturing network data

Summary by NHIP

Dynamic Network Data Capture

The system identifies security risks from cloud-based event data and sends configuration information to remote agents to generate additional data. Agents produce new event attributes only after a risk is found and stop generation after a specified period expires.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

US9843598B2, drawing sheet 1
Sheet 1 of 18

Term

8.1 yearsleft in the term

Expires 30 October 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

30 claims: 3 independent, 27 dependent

  1. 1
    Broadest claimClaim Score 72, broad(NHIP)A computer-implemented method, comprising:receiving event data generated by a remote capture agent running in a cloud-based computing environment, the event data generated based on network traffic monitored by the remote capture agent and involving at least one resource running in the cloud-based computing environment;identifying a security risk based on the event data received from the remote capture agent;and in response to identifying the security risk, sending configuration information to the remote capture agent, the configuration information used by the remote capture agent to generate additional event data.
  2. 14
    An apparatus, comprising:one or more processors;and a non-transitory computer readable storage medium storing instructions which, when executed by the one or more processors, cause the apparatus to: receive event data generated by a remote capture agent running in a cloud-based computing environment, the event data generated based on network traffic monitored by the remote capture agent and involving at least one resource running in the cloud-based computing environment;identify a security risk based on the event data received from the remote capture agent;and in response to identifying the security risk, send configuration information to the remote capture agents, the configuration information used by the remote capture agent to generate additional event data.
  3. 23
    A non-transitory computer-readable storage medium storing instructions which, when executed by one or more processors, cause performance of operations comprising:receiving event data generated by a remote capture agent running in a cloud-based computing environment, the event data generated based on network traffic monitored by the remote capture agent and involving at least one resource running in the cloud-based computing environment;identifying a security risk based on the event data received from the remote capture agent;and in response to identifying the security risk, sending configuration information to the remote capture agent, the configuration information used by the remote capture agent to generate additional event data.